Security is not an afterthought.

Your emails carry sensitive data: password resets, invoices, personal information. We treat every message with the level of security it deserves.

How we protect your data

Security is woven into every layer of our architecture, from the network edge down to the database.

Encryption everywhere

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Your API keys are hashed and never stored in plaintext.

Infrastructure security

Our infrastructure runs on hardened, isolated environments. We use Amazon Web Services with VPC isolation, security groups, and automated patching.

Authentication & access control

Unique server tokens and API keys with role-based access control. Team members can be granted granular access to specific servers.

Monitoring & logging

24/7 uptime monitoring with automated alerting. All API access is logged and auditable. Anomalous activity triggers immediate investigation.

Abuse prevention

Progressive rate limiting for new accounts, automatic suppression of bounced addresses, and heuristic-based detection of spam patterns.

Data isolation

Each account's data is logically isolated. Message streams keep transactional and promotional emails separated to protect your sender reputation.

Compliance & certifications

We continuously invest in meeting and exceeding industry standards for data security and privacy. Our commitment to compliance isn't just about checking boxes. It's about earning your trust.

Security questions?

Reach out to security@postject.com for our security questionnaire or to report a vulnerability.

SOC 2 Type II compliance roadmap in progress
GDPR-aligned data processing and retention policies
CAN-SPAM and CASL compliant sending practices
Regular third-party penetration testing
Responsible disclosure program for security researchers
Automated vulnerability scanning in CI/CD pipeline